paper-slides

Warn

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill makes extensive use of the Bash(*) tool to perform system-level operations, including symlinking files, running latexmk/pdflatex for compilation, and executing Python scripts. This broad access is necessary for its function but increases the impact of potential command injection if input parameters are not properly sanitized.
  • [DYNAMIC_EXECUTION]: In Phase 7, the skill dynamically generates a Python script (slides/generate_pptx.py) and executes it using python3. While intended to facilitate PowerPoint export, runtime script generation and execution is a high-risk pattern that can be exploited to run arbitrary code if the generation logic is influenced by malicious input data.
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses a significant attack surface for indirect prompt injection as it ingests untrusted content from LaTeX files (paper/sections/*.tex) and potentially external style references.
  • Ingestion points: Reads local .tex files and external sources via the --style-ref argument.
  • Boundary markers: The instructions do not specify the use of clear delimiters or 'ignore' instructions when processing this content.
  • Capability inventory: The skill has Bash(*) access, file write capabilities, and the ability to execute generated Python code.
  • Sanitization: There is no mention of escaping or sanitizing the content extracted from the paper before it is used to generate slides or scripts.
  • [EXTERNAL_DOWNLOADS]: The STYLE_HELPER logic (extract_paper_style.py) accepts HTTP(S) URLs and arXiv IDs as sources. This results in the fetching of external, potentially untrusted content into the skill's processing pipeline.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 15, 2026, 02:08 PM
Security Audit — agent-trust-hub — paper-slides